Vulnerability Description
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First, then LDAP”.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Thinkagile Hx5530 Firmware | < 2.93_afbt30p |
| Lenovo | Thinkagile Hx5530 | - |
| Lenovo | Thinkagile Hx7530 Firmware | < 2.93_afbt30p |
| Lenovo | Thinkagile Hx7530 | - |
| Lenovo | Thinkagile Vx3331 Firmware | < 2.93_afbt30p |
| Lenovo | Thinkagile Vx3331 | - |
| Lenovo | Thinkagile Hx Enclosure Firmware | < 3.72_tei388s |
| Lenovo | Thinkagile Hx Enclosure | - |
| Lenovo | Thinkagile Hx1021 Firmware | < 3.72_tei388s |
| Lenovo | Thinkagile Hx1021 | - |
| Lenovo | Thinkagile Hx1320 Firmware | < 8.88_cdi3a4a |
| Lenovo | Thinkagile Hx1320 | - |
| Lenovo | Thinkagile Hx1321 Firmware | < 8.88_cdi3a4a |
| Lenovo | Thinkagile Hx1321 | - |
| Lenovo | Thinkagile Hx1331 Firmware | < 2.93_afbt30p |
| Lenovo | Thinkagile Hx1331 | - |
| Lenovo | Thinkagile Hx1520-R Firmware | < 8.88_cdi3a4a |
| Lenovo | Thinkagile Hx1520-R | - |
| Lenovo | Thinkagile Hx1521-R Firmware | < 8.88_cdi3a4a |
| Lenovo | Thinkagile Hx1521-R | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/LEN-118321Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-118321Vendor Advisory
FAQ
What is CVE-2023-29057?
CVE-2023-29057 is a vulnerability with a CVSS score of 7.3 (HIGH). A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be confi...
How severe is CVE-2023-29057?
CVE-2023-29057 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-29057?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Thinkagile Hx5530 Firmware, Lenovo Thinkagile Hx5530, Lenovo Thinkagile Hx7530 Firmware, Lenovo Thinkagile Hx7530, Lenovo Thinkagile Vx3331 Firmware.